Security Engineer IV - API/Cloud Security
Role details
Job location
Tech stack
Job description
Join our team as a Security Engineer IV and contribute to the safeguarding of our information system resources and assets. We're seeking a team player with a positive attitude, drive and the ability to collaborate closely with our security team. In this role, you'll be responsible for ensuring that our security systems align with Information Security policies and standards while supporting our firm's business objectives., * Perform administration of API Security, Cloud and SaaS Security Posture management, AI security tooling and other firm platforms as needed
- Participate in troubleshooting efforts to resolve day to day issues
- Involvement in Agile methodologies to build out our security platforms
- Find gaps in security controls and be able to recommend possible resolutions
- Participate in daily operational work that comes with large enterprise networks
- For some functions, there may be requirements for on-call work outside normal business hours and scheduled tasks occurring outside business hours
- Provide technical leadership and complete complex system level assignments
- Design, implement, and support API security controls across enterprise applications, cloud services, and third-party integrations
- Lead investigations and remediation efforts for API-related security incidents, vulnerabilities, and compliance findings
- Analyze API traffic patterns and security telemetry to identify anomalous behavior, abuse, and potential attacks
- Provide technical guidance and mentoring to junior engineers and security analysts on API security best practices and secure coding principles
Requirements
- Bachelor's degree (preferred) in Computer Science, Management Information Systems, related field or related work experience
- 5+ years of experience in cybersecurity, application security, API security, or related engineering disciplines
- Knowledge and understanding of security systems, risks, concepts and terminology.
- Hands on experience with the security aspects of critical technologies (e.g., Linux, UNIX, Proofpoint, Windows, Web, LDAP, DBMS, Network, Firewalls, IDS/IPS, Data Loss Prevention (DLP), API Security, DNS, Vulnerability Assessment Tools)
- An intermediate to advanced understanding of at least one of the following environments; API Security, CSPM, SSPM or AI Security is highly preferred
- An intermediate understanding of Azure Cloud environments, controls and architecture is preferred.
- Comprehension of basic scripting languages (e.g., shell, PERL, Visual Basic, PHP, Python) is preferred.
- Ability to diagnose security, network, and system issues
- Understand infrastructure architecture - networks, security tools, operating systems and provides input to leaders about the impact of these components
- Strong understanding of API security risks, including OWASP API Security Top 10 vulnerabilities and modern attack techniques
- Ability to effectively communicate technical risks and remediation recommendations to both technical and non-technical stakeholders
- Experience working with API Security tooling in containerized environments
Benefits & conditions
At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received.
Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones
Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones